🔐 CVE Alert

CVE-2024-2542

MEDIUM 6.4

Jotform Online Forms <= 1.3.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode

CVSS Score
6.4
EPSS Score
0.0%
EPSS Percentile
0th

The Jotform Online Forms – Drag & Drop Form Builder, Securely Embed Contact Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-32527 is likely a duplicate of this issue.

CWE CWE-79
Vendor jotform
Product online forms — customizable payment, contact, quiz, survey form builder – jotform
Published May 2, 2024
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for jotform online forms — customizable payment, contact, quiz, survey form builder – jotform

Be the first to know when new medium vulnerabilities affecting jotform online forms — customizable payment, contact, quiz, survey form builder – jotform are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

jotform / Online Forms — Customizable Payment, Contact, Quiz, Survey Form Builder – Jotform
0 ≤ 1.3.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/90c34a01-a0d1-4305-b74b-b5a568a42b13?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3073311%40embed-form%2Ftrunk&old=2981633%40embed-form%2Ftrunk&sfp_email=&sfph_mail=#file1

Credits

Krzysztof Zając